BTW, Do you know if that ppp problem (Fw: [Bugme-new] [Bug 4381] New:
When i try to start a pppoe conn., crash at net/core/skbuff.c:91) was
already fixed? Otherwise I'd suggest that the reporter should capture
a crash again with this patch applied.

Unfortunately the reporter says that he can't reproduce it.
However, I have the suspicion that this is really the same as the
vpnc/tun bug (4279) that prompted you to make the self-modification
fix to tun.c.
Now there is no doubt that your patch fixed a real bug in tun.c.
However, I don't think it could have caused the crash in 4279.
The reason is that the crash dump shows that the length that
was supplied to skb_put is in fact positive (0xe4 in one case
and 0xf4 in another).

You're probably right, I only spent a few minutes looking for a
possible reason. Unfortunately the skb_over_panic() output wasn't
included in the report.

As soon as I get confirmation from the submitter that he can
still reproduce this I'll get him to try your debugging patch.